Index of /openstack/arch/

NameLast ModifiedSizeType
../ -  Directory
README.txt2015-Oct-18 23:48:451.5Ktext/plain
arch-openstack-2017-10-08-06-48-image-bootstrap- 06:51:021.4Gapplication/octet-stream
arch-openstack-2017-10-09-06-48-image-bootstrap- 06:51:091.4Gapplication/octet-stream
arch-openstack-2017-10-10-06-46-image-bootstrap- 06:49:071.4Gapplication/octet-stream
arch-openstack-2017-10-11-06-50-image-bootstrap- 06:52:181.4Gapplication/octet-stream
arch-openstack-2017-10-12-06-48-image-bootstrap- 06:50:401.4Gapplication/octet-stream
arch-openstack-2017-10-13-06-50-image-bootstrap- 06:52:311.4Gapplication/octet-stream
arch-openstack-2017-10-14-06-47-image-bootstrap- 06:49:511.4Gapplication/octet-stream
arch-openstack-2017-10-15-06-46-image-bootstrap- 06:49:001.4Gapplication/octet-stream
arch-openstack-2017-10-16-06-44-image-bootstrap- 06:46:231.4Gapplication/octet-stream
arch-openstack-2017-10-17-06-50-image-bootstrap- 06:53:011.4Gapplication/octet-stream
arch-openstack-2017-10-18-06-50-image-bootstrap- 06:52:301.4Gapplication/octet-stream
arch-openstack-2017-10-19-06-51-image-bootstrap- 06:53:501.4Gapplication/octet-stream
arch-openstack-2017-10-20-06-43-image-bootstrap- 06:46:071.4Gapplication/octet-stream
arch-openstack-LATEST-image-bootstrap.qcow22017-Oct-20 06:46:071.4Gapplication/octet-stream

   The images are *experimental* and work in progress.

   The latest image is the best.
   Known issue are tracked at:

Images were created running

  image-bootstrap --openstack DISTRO .. LOOP_DEVICE

with image-bootstrap from:

If the images have "bugs", the generator has a bug.
If you find things that need fixing, please file a bug against
image-bootstrap at GitHub.  Thank you!

image-bootstrap is downloading files through SSL and verifies downloads
using GnuPG.  That's the good part.  However:

 * The generating server is not air-gapped and therefore exposed
   to attacks from the internet.  Someone could hack this server
   and manipulate the image-generation code.

 * The resulting images are not signed and you are downloading
   via non-SSL HTTP right now.  Detecting man-in-the-middle
   is going to be tricky.

For the Arch images, I hope to convince someone of the Arch master keys
team members to run image-bootstrap, to sign the results and upload them just
like the Arch bootstrapping images.  That would be something you could
trust as much as you trust the Arch bootstrapping images.

Before we have that, the secure way is to run image-bootstrap yourself.

I would like to thank the kind folks at
for providing this virtual server, its storage and traffic
free of cost to me.  Many thanks!